Attackers rent verified Google ad accounts to hide Hyperliquid clones behind nested iframes

NewsFri, 14 Aug 2026 11:56:13 UTC3 hours ago
Attackers rent verified Google ad accounts to hide Hyperliquid clones behind nested iframes

A paid Google search ad directed a Hyperliquid user to a fake version of the exchange, causing them to lose about $550,000 in USDC, according to FlashRescue co-founder Darcy.

Darcy flagged the theft in a post Thursday, pointing to blockchain records that map the money’s exit.

What the on-chain trail shows

Data from Arkham Intelligence revealed three USDC transfers under one transaction hash. The bulk of it, some $440,000, went to 0x98b276…13C55.

There were two other smaller transfers, of about $82,500 and $27,500, to 0x93b6B2…d6D1 and 0x6fE314…B566, respectively.

Google shut down the account behind the ad. Scammers have used paid search against DeFi users since 2020, when fake Balancer and Uniswap ads went after private keys and wallet approvals.

Why do search ads keep slipping through?

Security Alliance (SEAL), a crypto-security nonprofit, explained how ads get past Google’s checks.

Hackers buy or steal verified Google advertiser accounts. Then they provide Google with a clean webpage hosted on a trusted domain.

… Continue reading the full article at the original source below.

Read from Source · cryptopolitan.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (cryptopolitan.com).

Related